Executive brief
A vulnerability exists in the Linux kernel's USB audio driver (ALSA). The system fails to properly check the size of data provided by USB audio devices using the UAC3 standard. A malicious or compromised USB device could provide specially crafted data to cause the system to read memory outside of intended boundaries, potentially leading to a system crash or the exposure of sensitive information.
Technical details
An out-of-bounds (OOB) read vulnerability (CWE-125) exists in the Linux kernel's ALSA usb-audio driver within the 'sound/usb/stream.c' component. The root cause is a lack of validation for UAC3 (USB Audio Class 3) cluster segment descriptors; specifically, the driver does not verify if the declared descriptor lengths match the actual data or fit within allocated buffer sizes. An attacker with physical access or the ability to emulate a USB device can provide malicious firmware descriptors to trigger OOB accesses. This can result in a denial of service (system crash) or information disclosure. Patches have been released across multiple stable kernel branches (4.19.y through 6.16.y).
Affected products
- Linux Linux Kernel 4.19 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-08-14: other: Patch authored by Takashi Iwai
- 2025-09-11: disclosed: CVE published
- 2026-01-09: advisory: NIST/NVD enrichment completed
References
- https://git.kernel.org/stable/c/1034719fdefd26caeec0a44a868bb5a412c2c1a5
- https://git.kernel.org/stable/c/275e37532e8ebe25e8a4069b2d9f955bfd202a46
- https://git.kernel.org/stable/c/47ab3d820cb0a502bd0074f83bb3cf7ab5d79902
- https://git.kernel.org/stable/c/786571b10b1ae6d90e1242848ce78ee7e1d493c4
- https://git.kernel.org/stable/c/799c06ad4c9c790c265e8b6b94947213f1fb389c
- https://git.kernel.org/stable/c/7ef3fd250f84494fb2f7871f357808edaa1fc6ce
- https://git.kernel.org/stable/c/ae17b3b5e753efc239421d186cd1ff06e5ac296e